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Modular verification is a technique used to face the state explosion problem often encountered in the 
verification of properties of complex systems such as concurrent interactive systems. The modular 
approach is based on the observation that properties of interest often concern a rather small portion 
of the system. As a consequence, reduced models can be constructed which approximate the overall 
system behaviour thus allowing more efficient verification. 

Biochemical pathways can be seen as complex concurrent interactive systems. Consequently, 
verification of their properties is often computationally very expensive and could take advantage of 
the modular approach. 

In this paper we report preliminary results on the development of a modular verification frame- 
work for biochemical pathways. We view biochemical pathways as concurrent systems of reactions 
competing for molecular resources. A modular verification technique could be based on reduced 
models containing only reactions involving molecular resources of interest. 

For a proper description of the system behaviour we argue that it is essential to consider a suitable 
notion of fairness, which is a well-established notion in concurrency theory but novel in the field of 
pathway modelling. We propose a modelling approach that includes fairness and we identify the 
assumptions under which verification of properties can be done in a modular way. 

We prove the correctness of the approach and demonstrate it on the model of the EGF receptor- 
induced MAP kinase cascade by Schoeberl et al. 

1 Introduction 

A big challenge of current biology is understanding the principles and functioning of complex biolog- 
ical systems. Despite the great effort of molecular biologists investigating the functioning of cellular 
components and networks, we still cannot provide a detailed answer to the question "how a cell works?". 

In the last decades, scientists have gathered an enormous amount of molecular level information. 
To uncover the principles of functioning of a biological system, just collecting data does not suffice. 
Actually, it is necessary to understand the functioning of parts and the way these interact in complex 
systems. The aim of systems biology is to build, on top of the data, the science that deals with principles 
of operation of biological systems. The comprehension of these principles is done by modelling and 
analysis exploiting mathematical means. 

A typical scenario of modelling a biological system is as follows. To build a model that explains the 
behaviour of a real biological system, first a formalism needs to be chosen. Then a model of the system 
is created, simulation is performed, and the behaviour is observed. The model is validated by comparing 
the results with the real experiments. The advantage of simulation is not only validation of laboratory 
experiments, but also prediction of behaviour under new conditions and automation of the whole process. 
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Simulation can give either the average system behaviour or a number of possible system behaviours. 
This may be insufficient when one is interested in analysing all the behaviours of a system. 

Model checking may be of help. This technique permits the verification of properties (expressed as 
logical formulae) by exploring all the possible behaviours of a system. This analysis technique typically 
relies on a state space representation whose size, unfortunately, makes the analysis often intractable for 
realistic models. This is true in particular for systems of interest in systems biology (such as metabolic 
pathways, signalling pathways, and gene regulatory networks), which often consist of a huge number of 
components interacting in different ways, thus exhibiting very complex behaviours. 

Many formalisms originally developed by computer scientists to model systems of interacting com- 
ponents have been applied to biology, also with extensions to allow more precise descriptions of the 
biological behaviours (U[4l[6l[9l[TH[T9l. Examples of well-established formal frameworks that can be 
used to model, simulate and model check descriptions of biological systems are lt6l [T4l[T5) . 

Model checking techniques have traditionally suffered from the state explosion problem. Standard 
approaches to the solution of this problem are based on abstractions or similar model reduction tech- 
niques (e.g. Ol)- Moreover, the use of Binary Decision Diagrams (BDDs) [ 8 ] to represent the state space 
(symbolic model checking) often allows significantly larger model to be treated 0. 

A method for trying to avoid the state space explosion problem is to consider a decomposition of 
the system, and to apply a modular verification technique allowing global properties to be inferred from 
properties of the system components. This approach can be particularly efficient when the modelled 
systems consist of a high number of components, whereas properties of interest deal only with rather 
small subset of them. This is often the case for properties of biological systems. Hence, for each 
property it would be useful to be able to isolate a minimal fragment of the model that is necessary 
for verifying such a property. If such a fragment can be obtained by working only on the syntax of the 
model, the application of a standard verification technique on the semantics of the fragment avoids the 
state explosion. 

In previous work we developed a modular verification technique in which the system of interest is 
described by means of a general automata-based formalism suitable for qualitative description of a large 
class of biological systems, called sync -programs, which supports modular construction [TTl[T2l . Sync- 
programs include a notion of synchronization that enables the modelling of biological systems. The 
modular verification technique is based on property preservation and allows the verification of properties 
expressed in the temporal logic ACTL to be verified on fragments of models. In order to handle mod- 
elling and verification of more realistic biological scenarios, we have proposed a dynamic version of our 
formalism along with an extension of the modular verification framework ifTUl . 

The long-term aim of our research is the development of an efficient modular verification framework 
specifically designed for biochemical pathways, and of a pathway analysis tool based on such a frame- 
work. Presently, we are at the first stages of the development of the modular verification framework. 
However, we already faced some problems whose solution required the definition of concepts related to 
the formal modelling of biochemical pathways and that we believe could be interesting not only in the 
context of modular verification. In particular, we defined a notion of fairness for biochemical pathways 
and a notion of molecular component of a pathway. The former is a well-known concept in concur- 
rency theory that could be useful to describe more accurately the dynamics of a pathway (in a qualitative 
framework). The latter is a notion relating species involved in the same pathway such that two species 
are considered to be part of the same molecular component if they can be seen as different states of the 
same molecule. As far as we know, the adoption of a notion of fairness in the context of biology is new. 
On the other hand, the notion of molecular component has been often implicitly used (for instance in the 
modelling of biological systems by means of automata), but now we provide new insight on this notion. 
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In this paper we report preliminary results obtained during the development of the modular verifica- 
tion framework. Modular verification requires either adopting a modular notation for pathway modelling 
or finding a way to decompose a pathway, simply expressed as a set of biochemical reactions, into a num- 
ber of modules. The approach that we choose to follow is in between these two alternatives. Actually, 
we assume the pathway to be expressed as a set of reactions satisfying some modularisation require- 
ments, and then we define a modularisation procedure that allows modules to be inferred from reactions. 
Modules will be molecular components, hence our modularisation procedure will allow us to consider a 
pathway not only as a set of reactions, but also as a set of entities interacting with each other (through 
reactions) and consequently changing state. 

Once the molecular components of a pathway are identified, we can use them to decompose the 
verification of a global pathway property into the verification of a number of sub-properties related 
with groups of components. To this aim we define a projection operation that allows a model fragment 
describing the behaviour of a group of components to be obtained from a model describing the whole 
pathway. Such a projection operation is actually an abstraction function, since the behaviour of the group 
of components will be over-approximated (i.e. the model will include behaviours that are not present 
in the model of the whole pathway). By considering a suitable temporal logic for the specification 
of properties (namely ACTL , a fragment of the CTL logic consisting only of universally quantified 
formulae) we can prove that properties holding in model fragments obtained by projection also hold in 
the complete model of the pathway. Nothing can be said, instead, of properties that do not hold in the 
the model fragment. 

In order to verify properties of complete pathway models or of model fragments it is possible to 
translate them into the input language of an existing model checking tool. Specifically, we use the 
NuSMV model checker Q, which is a well-established and efficient instrument. 

We demonstrate the modular verification approach on the model of the EGF receptor-induced MAP 
kinase cascade by Schoeberl et al. ll20l and we discuss how we plan to continue the development of the 
approach to improve its efficiency. 

2 Modelling Biochemical Pathways with a Notion of Fairness 

In biochemistry, metabolic pathways are networks of biochemical reactions occurring within a cell. The 
reactions are connected by their intermediates: products of one reaction are substrates for subsequent 
reactions. Reactions are influenced by catalysts and inhibitors, which are molecules (proteins) which 
can stimulate and block the occurrence of reactions, respectively. For the sake of simplicity we do not 
consider inhibitors in this paper, although they could be easily dealt with. 

2.1 Syntax and semantics of the modelling notation 

Given an infinite set of species S, let us assume biochemical reactions constituting a pathway to have the 
following form: 

n,...,r n ->■ px, ...,p n > {ci,...,c m } 

where rj,pj and cs, for suitable values of j, are all in S. We have that r,s are reactants, pjs are products 
and cys are catalysts of the considered reaction. Given a reaction R we define re(R) = {r\, . . . ,r n }, 
pro(R) = {pi, . . . ,p n '}, and cat(R) = {c\, . . . ,c m }. We denote the set of species involved in reaction R as 
species(R) = re(R)Upro(R)Ucat(R). 
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A pathway P is simply a set of reactions, P = {Ri ,Rn}- Given a pathway P, we can infer the set 
of species involved in it as species (P) = \J ReP species (R). 

The dynamics of a pathway can be described at several different levels of abstraction. The most 
precise level consists of a quantitative description in which quantities (or concentrations) of species are 
taken into account, as well as reaction rates in either a deterministic or a stochastic framework. At a 
more abstract level reaction rates can be ignored. Ultimately, also quantities of species can be ignored 
by considering only their presence (or absence) in the considered biochemical solution. The less abstract 
description level is obviously the most precise, but also the most difficult to treat with formal analysis 
techniques. The more abstract levels are more suitable for the application of formal analysis techniques 
and are often precise enough to provide some information on the role of the species and of the reactions 
involved in the pathway. We choose to adopt the most abstract description level, and hence we define a 
qualitative formal semantics of pathways in which species can only be either present or absent. 

The dynamics of a pathway starts from an initial state representing a biochemical solution and is 
determined by the reactions. A reaction essentially causes the appearance of some new species in the 
biochemical solution. Actually, we choose to interpret the effect of a reaction depending on whether 
it is catalysed or not. In our interpretation a reaction without catalysts creates the products but does 
not consume the reactants. We choose this interpretation since non-catalysed reactions usually reach a 
steady-state of dynamic equilibrium in which both reactants and products are present in the biochemical 
solution. On the other hand, a reaction favoured by catalysts usually tends to be performed as long 
as there are reactants. Therefore, in our interpretation a reaction with catalysts creates the products 
and consumes the reactants. This choice implies that a reversible reaction in which both directions are 
catalysed, which frequently occurs in biological pathways, oscillates between two states. This is realistic 
in some cases (oscillatory behaviours) but not always. We leave a more detailed treatment of this aspect 
as future work. 

Lastly, we assume that all of the catalysts are required to be present in order for the reaction to 
occur. Alternative combinations of catalysts that may enable the reaction should be modelled as different 
reactions having the same reactants and products. 

Formally, given a pathway P and a set so Q species (P) representing species present in the initial state 
of the system, the semantics of P is given by the labelled transition system (& (species (P)), So, — >r), 
where [species (P)) is the powerset of the set of species of P, meaning that each state of the LTS 
is a configuration of the pathway indicating which species are present. We use the boldface notation, 
e.g. s to denote states in the semantics, while a simple s denotes a species which means either a reactant, 
a product or a catalyst. Furthermore, — >r: & [species (P)) x P x & (species (P)) is the least transition 
relation satisfying the following inference rules 

re(R) C s, pro(R) % s, ^ cat(R) C s re(R) C s, pro(R) £ s, cat(R) = 

(cat) (no-cat) . 

s -> (s\re(R))Upro(R) s ^sU pw(R) 

Rules (cat) and (no-cat) formalise the dynamics of reactions in the presence and absence of catalysts, 
respectively. Both rules contain an assumption which states that the reaction does not occur if its products 
already exist. Note that thanks to this optimisation transitions that do not change the state of the system 
are excluded, which is convenient for the verification as the size of the transition system is smaller but 
the set of properties that hold stays the same. We denote the semantic function as LTS, i.e. LTS : P i-> 
(0> (species (P)), so, ->r). 

A path in LTS(P) can be either a finite sequence So,/?o,si,/?i, . . . ,s n or an infinite sequence so,Ro, 

R- 

Si,R\, . . . where for all i, Si is a state and Rj is a reaction and Sj -4- Si + i is a transition in LTS(P). The 
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path consisting only of the initial state so is denoted e. In this paper we consider only maximal paths, 
corresponding to behaviours of the pathway in which as long as some reactions can occur, the pathway 
activity does not halt. It is worth noting that maximal paths are not necessarily infinite, as a state where 
no reactions can occur has no successor and a path leading to such a state is finite. 

2.2 Fairness 

In order to describe the behaviour of a pathway more accurately we consider a notion of fairness. We 

k[ k2 

motivate it by considering a quantitative system consisting of four reactions A — > B {D},B — )■ A {D}, 

A —V C { D } and C A { D }, where k\, hi, k^ and k$ are the reaction rates. By performing the 
qualitative abstraction, we get a pathway containing reactions 7?i = A — > B {D} and R2 = B — > A { D }, 
7?3=A — > C and R4 = C — > A {£>}, whose semantics as defined above includes behaviours 

such as the one where 7?3 never occurs. Such a behaviour is a qualitative abstraction which is not correct, 
since the standard quantitative dynamics ruled by the law of mass action would imply that both Ri and 
R3 occur with a frequency proportional to their kinetic rates. Actually, in a stochastic setting both R\ 
and 7?3 would infinitely occur with probability 1 . A correct qualitative abstraction of our system should 
therefore only include maximal paths in which both 7?i and Rj occur infinitely many times. 

A concept from concurrency theory that allows to specify the correct behaviour is fairness, which 
stipulates that reactions should compete in a fair manner. We consider the well-known notion of strong 
fairness lfl3ll . also called compassion, which requires that if a reaction is enabled (ready to occur) in- 
finitely many times, then it will occur infinitely many times. 

Technically, fairness is specified by a linear temporal logic (LTL) formula. LTL ifTTll is built up from 
formulae over a finite set of atomic propositions S, therefore a s G 5 is a LTL formula and if / and g are 
LTL formulae, then so are -1/, fVg,Xg and f U g where X is read as next and U as until. Additional 
logical operators can be defined, true = s V -^s, false = -^true, f Ag = -<(-<f V ->g) and f g = -1/ V g, 
additional temporal operators eventually F g = true U g and globally G g = ->F ->g. A LTL formula can 
be satisfied by a maximal path % in LTS(P) as described by the satisfaction relation \=ltl- n ^ltl s if 
n = s,R,7i',n \= LTL "\g if not % \= LTL g, n \= LTL f Vg if % ^ LTL f or n ^ LTL g, n ^ LTL X g if % = s ,R, %' and 
^ltl g, and finally n \=ltl fUgif there is an i > such that n = so,Ro,Si,R\, . . . and s,,/?,-, n,- \=ltl f 
and forall < k < i, Sk,Rk,7lk ^ltl g- 

Fairness is expressed by formula <1>, and a maximal path % is fair iff it satisfies <!>, i.e. % \=ltl < J > - We 
have 

<J> <=^ f\ (GF enabled (R) -> GF occurred (R)) 
ReP 

where enabled(R) <;=^ ((Arere(R) r ) A (Vpe pro (R) ~^P) A (Acecat(R) c )) an d the satisfaction of proposition 
occurred{R) is defined as %' \=ltl occurred(R) iff there is a path % such that % = s,R, %' . 

It should be noted that our fairness neither requires all reactions to occur infinitely nor requires fair 
paths to be infinite. 

2.3 Modelling the EGF receptor-induced MAP kinase cascade 

We apply our modular verification approach to a well-established computational model of the EGF sig- 
nalling pathway. We consider the model of the MAP kinase cascade activated by surface and inter- 
nalised EGF receptors, proposed by Schoeberl et al. in ll20l . This model includes a detailed description 
of the reactions that involve active EGF receptors and several effectors named GAP, ShC, SOS, Grb2, 
RasGDP/GTP and Raf. Moreover, the model describes the activity of internalised receptors, namely 
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receptors that are no longer located on the cell membrane, but on a vesicle obtained by endocytosis and 
floating in the cytoplasm. Such internalised receptors continue to interact with effectors and to contribute 
to the pathway functioning, but actually the pathway can be seen as composed by two almost identical 
branches: the first consisting of the reactions stimulated by receptors on the cell membrane and the 
second consisting of reactions stimulated by internalised receptors. 

A diagram representing all of the reactions of the pathway considered in the model is shown in 
Figure Q] In the figure, species are identified by a short name, but also by a number (in black) in the 
interval [1—60]. Arrows represent reactions, which are also associated with an identifier (in grey) in the 
interval [vO — vlOl]. Note that the two branches of the pathway are partially combined in the figure. In 
particular, the representation of most of the species is combined with the representation of its internalised 
counterpart. In such cases, the number between brackets denotes the number identifying the internalised 
species. The same holds for reactions: in many cases an arrow denotes both a reaction stimulated by 
receptors in the cell membrane and the corresponding reaction stimulated by internalised receptors. 

The set of reactions constituting the pathway can be trivially reconstructed from the diagram in Figure 
[Q The only non-trivial aspect is related with the presence in the diagram of some reactions in which one 
reactants is actually acting as a catalyst. For instance, this happens in the case of the reactions involving 
Raf* and MEK, in which Raf* initially binds MEK and then releases it phosphorylated. We describe 
these two reactions in the diagram with the following single catalysed reaction: 

MEK -»■ MEK-P { Raf* } 

Other species acting as catalysts are MEK-PP, Phosphatasel, Phosphatase2 and Phosphatase3. By 
applying the same transformation also to the reactions they are involved in we obtain a pathway consti- 
tuted by 80 reactions. We call this pathway Pegf- 

We recall that fairness requires that a reaction that is infinitely often enabled is also infinitely often 
performed. This prevents starvation situations to happen among reactions. In the case of Pegf the two 
branches of the pathway include reactions that could be involved in infinite loops (e.g. the reactions 
involving MEK and ERK). This means that the semantics of the pathway includes behaviours in which 
only one branch executes forever even if the other is constantly enabled. Such unrealistic behaviours are 
excluded by the adoption of fairness. 

3 Identification of Molecular Components 

In this section we argue, that under conditions often found in practice, a pathway can be decomposed into 
components, which, as it will be shown in the following sections, can be used for modular verification. 

3.1 Assumptions 

Intuitively, a species can be seen as a part of a "state" or "configuration" of a more general system 
component, and a reaction can be seen as a synchronised state change of a set of such system components. 
In order to view a pathway through this optics, it is convenient to assume that the pathway has equal 
number of reactants and products (which is not the case in general). Moreover, we assume a positional 
correspondence between the reactants and the products, in particular we assume that product pj is the 
result of the transformation of reactant r ; by the reaction. In our experience, it is usually possible to 
translate a reaction of a pathway into such a "normal form". Reactions of cellular pathways very often 
represent bindings (and unbindings) of well-defined macromolecules, such as proteins and genes, to 
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form (or to break) complexes either with other macromolecules or with small molecules such as ions 
and nutrients. Also conformational changes are common, in which a protein (or a complex constituted 
by a few proteins) changes its own "state". If we consider a complex not as a single entity, but as a 
combination of macromolecules we have that all of the mentioned kinds of reaction do not change the 
number of (macro)molecules in the system. Hence, it should be possible to model them with the reactions 
in the form we assume here. For the moment we leave the translation of reaction into the assumed form 
to the modeller. 

In Section [27TI we have introduced the syntax of the modelling formalism of biochemical pathways, 
in which a reaction is allowed to have a different number of reactants and products. 

3.2 Components identification 

Let us, thus, assume that the pathway P consists of reactions in the following form: 

n,...,r n ->• p u ...,p n {ci,...,c m }. 

Such a form enables us to identify a set of components / that constitute the pathway. Now we present an 
algorithm that given a pathway P returns the set of components / along with the partition of the set of 
species belonging to respective components. 

We illustrate the intuitive idea on an example. Each reaction can be seen as a synchronisation of 
components. For example reaction r\,r2 — > P\,Pi { c } can be interpreted as a synchronisation of 
three components: one that changes its state from a state where r\ holds into a state where p\ is present 
and r\ is not, another component that changes its state from a state where ri holds to a state where P2 
is present and r2 is not, and a component which participates passively and stays in a state where c is 
present. Since we suppose that only one reaction takes place at a time in the whole system, the states 
of all the components do not change other than those involved in the reaction in the way we described. 
From the example we can see that species r\ and p\ belong to the same component. Similarly r2 belongs 
to the component that contains p2, while c is from a separate one. 

The algorithm follows. We start by assuming that each species belongs to a different component and 
we refine this assumption by iterating over the reactions constituting P. The result of the algorithm is a 
mapping map assigning each species to its component. 

Algorithm 1 Algorithm to partition species into different components 
Let map : 5 1— > I be an injective mapping 
for all R in P do 

for all r; in re[R) do 

{p h-> map(rj) Vp € {s € S I map(s) 
s^map(s) otherwise 

end for 
end for 
return map 



The algorithm updates the mapping by unifying the elements assigned to reactants and products in 
the same position in a reaction, and this is done for all reactions in the pathway. 

The set of components comp(P) = I of pathway P is the image of mapping map. Components of a 
reaction R denoted, using the same notation, as comp(R) are defined as comp({R}). 



= map(pj)} 
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3.3 Initial state 

We adopt a semi-automatic heuristic procedure to rind an initial state of the pathway. The idea is the 
following: for each species s in species{P), if there is no reaction creating it (i.e. if s \J ReP pro(R)) then 
in the initial state s is present. This means that species that cannot be produced are assumed to be present 
in the initial state. Otherwise their presence in the model would not be meaningful. Subsequently, we 
resort again to the partitioning of species according to components to find other species to be inserted. 
In particular, we find those components containing no species present in the previous phase. These 
components must contain loops, hence we choose manually some of their species to insert. All other 
species are assumed absent. 



3.4 Visualisation of component interaction 

A component interaction graph can be drawn which visualises the components of a pathway and their 
interactions. It is a directed graph in which vertices are system components (elements of /) and edges 
connect components that are involved together in a reaction. If two components are both involved as 
reactants (and consequently products), the edge connecting them will not be oriented (displayed as bidi- 
rectional). If one of the two is involved as reactant and the other as catalyst, then the edge will start from 
the vertex representing the latter to the vertex representing the former. There is no edge between vertices 
representing components involved in the same reactions only as catalysts. 



3.5 The model 

The model Pegf is made up of 143 species and 80 reactions. It is in the correct form assumed in 
Section [37X1 and no preprocessing is needed. After performing the components identification procedure, 
14 components are identified. On Figure [2] we can see the component interaction graph of Pegf- Each 
node of the graph is labelled by the intuitive name of the component that we have chosen. 

Visually, we can do some simple observations on the component interaction graph. We can identify 
enzymes like Phosphatase 1, Phosphatase2 and Phosphatase3. We can see the first part of the pathway 
corresponding to the EGF receptor and its interaction with effectors, and its connection to the MAP 
kinase cascade through the component RasGDP. 




Figure 2: Component interaction graph of Pegf 
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4 Modular Verification 

In this section we define a modular verification technique for pathway models. We proceed by defining 
the projection of a pathway with help of the identified components. Such a projection can be seen as an 
abstraction, giving rise to abstract pathways. We prove that a successful verification of a property in the 
abstraction implies its truth in the original model. 

4.1 Abstract pathways: syntax, semantics and fairness 

We are interested in analysing only a portion of the entire pathway, in particular a portion induced by 
only a subset of all components. Let / = comp(P) and J C /, we define the projection of a pathway P 
onto / as an abstract pathway P \J. 

We will need an extension of function species, abusing the notation, which operates on a component 
set: species(J) = {s£ species{R) \ R s.t. comp(R) DJ ^ 0}. 

Definition 1. An abstract pathway P\J is a pair (PR,AR), where 

• PR = {ReP\ comp(R) C /} 

• AR = \J RePjComp{R)nJ ^{re(R)\J -> pro{R)\J {cat{R)\J}, re{R)\J -> re{R)\J {cat(R)\J}} 

comp(R)n(I\J)jt(& 

where the projection of a set of species u CS is defined as u \J = {s £ u \ s G species (J)}. 

An abstract pathway consists of two sets of of reactions: PR contains reactions which influence only 
components inside J, and AR contains projections of reactions that influence components both inside and 
outside /. Reactions in PR are exactly as in P, since all of the species involved in such reactions are 
considered in the abstract pathway. On the other hand, reactions in AR are obtained from the reactions 
in P which involve species both from some components in / and from some components not in J. For 
each of such reactions in P we have two reactions in AP: one describing the situation in which species 
not in species(J) are assumed to be configured such that the reaction can occur, and the other describing 
the opposite situation. In the first case the reaction in AR produces some products; in the second case the 
reaction in AR performs a self-loop (i.e. it does not change the state). 

The abstract pathway semantics is defined as LTS a '■ P\J >-> LTS(PRUAR), that is by using the 
standard semantics LTS on the projected reactions in both PR and AR. 

What changes with respect to the pathway model is the definition of fairness. In fact, in this case 
fairness constraints can be applied only to reactions in PR since reactions in AR consist of pairs of 
reactions always applicable at the same time and in which it is reasonable to assume that one of the two 
is always preferred (describing the situation in which the corresponding reaction in R is always enabled 
or disabled). We define the notion of abstract fairness as 

<J> a ^> f\ (GF enabled (R) ->■ GF occurred (/?)). 
RePR 

Here the compassion is only required for reactions from PR. 

Note that a pathway is a special case of abstract pathway, since the semantics of P is equivalent 
(isomophic) to that of P \I and in this case also <I> = <& a holds. 
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4.2 Logic for specifying properties 

Properties of pathways are specified in temporal logic with species as atomic propositions. 

The logic we consider is a fragment of the Computation Tree Logic CTL. Following Attie and Emer- 
son Ol, we assume the logic ACTL for specification of properties. ACTL is the "universal fragment" 
of CTL which results from CTL by restricting negation to propositions and eliminating the existential 
path quantifier and ACTL - is ACTL without the AX modality. 

Definition 2. The syntax of ACTL - is defined inductively as follows: 

• The constants true and false are formulae, s and —>s are formulae for any atomic proposition s, 
where the set of atomic propositions AP are the set of all species S. 

• fffi8 are formulae, then so are f A g and fVg. 

• Iff,g are formulae, then so are A[f U g] andA[f U w g]. 

We define the logic ACTL7 to be ACTL - where the atomic propositions are drawn from APj = 
species (J). Abbreviations in ACTL - : AFf = A[true U f] and AGf = A[f U w false]. 

Properties expressible by ACTL - formulae represent a significant class of properties investigated in 
the systems biology literature as identified in |fl6l , such as properties concerning exclusion ("It is not 
possible for a state s to occur"), necessary consequence ("If a state Si occurs, then it is necessarily 
followed by a state S2"), and necessary persistence ("A state s must persist indefinitely"). 

On the other hand, properties as occurrence, possible consequence, sequence and possible persistence 
are of inherently existential nature, and are not expressible in ACTL - . 

Definition of the semantics of ACTL - formulae on labelled transition system LTS(P) follows. Note 
that only fair maximal paths are considered. 

Definition 3. Semantics of ACTL - . We define LTS(P),s \=q, f (resp. LTS(P),n \=® f) meaning that f is 
true in structure LTS(P) at state s ( resp. fair maximal path %). We define h<j> inductively: 

• LTS(P),s 1=* true. LTS(P),s \f false. LTS(P),s \=® s iffs(s) = tt. LTS(P),s hj> ^s iffs(s) =ff. 

• LTS(P) ,s \=<& f Ag iffLTS(P) ,sN$/ and LTS(P) ,s\=®g 
LTS(P),s ^fVgiffLTS(P),s N / orLTS(P),s N g. 

• LTS(P),S 1=0 Af iff for every fair maximal path K = (s,R, . . .) in LTS(P) : LTS(P), 7t 1=$ /. 

• LTS(P),7C 1=$ / iff LTS(P),s 1=$ /, where s is the first state of K 

• LTS(P),7t\=*fAg iffLTS(P) ,71 ^f and LTS(P) , K N g. 
LTS(P) ,K^fVg ijfLTS(P) ,K^for LTS(P) ,7Z\=<j>g. 

• LTS(P),K \=q, f U g iff Ti = (so,/?o>Si,/?i, • • •) an d there is m € N such that LTS(P),s m N$ g 
and for all m' <m: LTS(P),s m i l=<j> /. 

• LTS(P),n N* / U w g iff 71 = (s ,/?o,Si,/?i, . . .) and for all m G N, ifLTS(P),s m , tyg 
for all m' <m then LTS(P) , s m 1=$ /. 

We assume t=$ a to be defined as t=$, but with abstract fairness <t> a replacing <!>. 
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4.3 Modular verification theorems 

Now we prove that in order to verify an ACTLJ property for a pathway P, it is enough to verify the 
same property in the abstract semantics of the abstract pathway P\J. The principle behind property 
preservation is that each path in the semantics of the modelled pathway must have a corresponding 
abstract path in the abstract semantics of a model obtained by projection. This, combined with the fact 
that ACTL~ properties are universally quantified (namely describe properties that have to be satisfied by 
all paths) ensure that if an ACTL~ property holds in the abstract semantics of the projection, then it will 
also hold in the semantics of the orginal model. In fact, for the components considered in a projection 
the semantics of the original model will contain essentially a subset of the paths of the projected model. 

ACTL~ properties are universally quantified, namely they they deal with all paths starting form a 
given initial state, and the fact that all original paths (more precisely their projections) are included 
amongst the paths of the projection. Thus if one proves that the property holds in the projection for all 
paths it will hold for all paths also in the original system. 

First we define the path projection, which from a path in semantics of a pathway with the set of 
components / removes transitions made by components outside of portion J QI and restricts the rest of 
transitions onto /. 

Definition 4. 

a ifn = e 

7t\J = < k'\J if K = s,R,7l' and comp(R)f] J = 

k S \J,R, k'\J ifn = s,R,7l' and comp(R) f]J ^ 

Follows the infinite path projection which ensures that the resulting traces are infinite. In case of a 
finite original trace it adds an infinite looping in the final state. 

Definition 5. Given % \J with initial state So we define % \°°J = % \J if % \J is infinite, otherwise if % \J = 
So,Rq, . . . ,s n _i, R n -i, s n we define n\°°J = n\J, (*,s„)°°, where (R,s)°° = R,s, (R,s)°°. We denote e\°°J = 
So,(*,So)°°<« s°°. 

Now we are in the position to present the crucial result, which states that a fair maximal path in the 
semantics of a pathway is either projected or infinitely projected into an abstractly fair maximal path in 
the abstract semantics of an abstract pathway. It is split in two lemmas, where the first one states that at 
least one of the projections is present as a maximal path in the abstract semantics. The second lemma 
proves the abstract fairness of the projections. 

Lemma 1. % € LTS(P) with % )= LTL <t> implies {% \J G LTS a {P \J) or % \°°J € LTS a {P \J)). 

Proof. Let us assume that n is a finite path, then we can prove that either (n \J € LTS a (P \J) or n \°°J G 
LTS a (P\J)) by induction on the path length. 

Case % = e. We have that % \J = % \°°J = e. Since % = e, the initial state so is such that no reaction is 
enabled in so- By the definition of abstract pathway semantics we know that the initial state of LTS a (P \J) 
is So \J. 

By definition of abstract pathway we have that P\J = (PR,AR). 

• If AR = 0, then since PR C P and there is no reaction in P that is enabled in so, there is also no 
reaction in PR that is enabled in so \J, and hence e G LTS a (P \J). 

• If AR / 0, then for each R G P\PRwe have in AR two reactions R\ ,/?2 as follows 

Ri = re(R) \J -> pro(R) \J { cat(R) \J } 
R 2 = re {R) \J ->• re(R) \J { cat{R) \J } 
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Note that if Ri is enabled, then also R2 is enabled. 

As before, since there is no reaction in P that is enabled in so, there is also no reaction in PR 
that is enabled in So[/. If there is some R2 enabled in So\J, then (/?2,Sof"/)°° G LTS a (P\J), that is 
£ \°°J G LTS a (P \J)). On the other hand, if there is no R2 enabled in so [/, then there is also no Ri 
enabled in the same state, hence e G LTS a (P\J), that is e \J G LTS a (P\J). 

Case it = s,R, it' . We distinguish two subcases: 

• comp(R) HJ = 0: s' is the initial state of it', so by induction hypothesis s'\J is the initial state 
of either it' \J or it' \°°J. Moreover, state, by definition of path projection, s\J = s' \J then s \J 
is the initial state of either it' \J or it' \°°J, which means that either it' \J = it \J G LTS a (P \J) or 
it'\°°J = it\°°J£LTS a {P\J). 

• comp(R) HJ 7^ 0: s' is the initial state of it', so by induction hypothesis s'\J is the initial state of 
either it' \J or it' \°°J. Moreover, in P \J there are R\ and R2 as above. Since R is enabled in s, R\ 
is enabled in s |7. Therefore either s \J,Ri , %' \J = it \J G LTS a (P \J) or s\J,R u %' \°°J = K \°°J G 
LTS a (P\J). 

Summarising, if % is a finite path, in all the possible cases we have that either n \J G LTS a (P \J) or 

n\~J€LTS a (P\J). 

Let us consider now the case in which % is infinite. We have two subcases: 

• %\J is finite: By the fairness assumption % \=ltl & it follows that if the path n\J is finite, then its 
final state is such that no reaction in PR is enabled. In fact, as a consequence of fairness, the only 
case in which n \J can be finite is when all of the reactions that are infinitely often enabled in n are 
performed only by components that are not in /. Hence, n \J is finite since it contains reactions 
that are not enabled infinitely often. Let % = K\ , K2, where K\ is the shortest (finite) prefix such that 
%2 contains only moves of reactions enabled infinitely often. It is easy to see that n \J = K\ \J and 
similarly as before we can prove by induction on the length of K\ that either 7l\ \J G LTS a (P \J) or 
K\ \°°J G LTS a (P\J). The fact that no reaction is enabled in the final state of n\J ensures that n\J 
is a maximal path of LTS a (P\J). 

• %\J is infinite: This case can be proved by showing that the relation between % and % \J described 
in the inductive case of the proof for a finite % is indeed an invariant property in the case of an 
infinite path it. 

□ 

Now we state and prove the second lemma. 
Lemma 2. it ^ltl ® implies it [J \=ltl and it \°°J \=ltl ^a- 

Proof. Suppose that it \=ltl i-e. it \=ltl Argp(GF enabled{R) — > GF occurred(R)). Let J Q I and 
P\J = (AR,PR). We want to prove that it\J ^ LTL <!>„, that is it\J \=ltl Arepr( gf enabled(R) -> 
GF occurred{R)) This holds because of two facts (1) and (2) that can be easily checked: for any re- 
action R from PR 

• s \=ltl enabled(R) implies s \J \=ltl enabled{R) (1) 

• s \=ltl occurred(R) implies s \J \=ltl occurred(R) (2) 
Analogously it\°"J ^ltl Argpr(^ enabled(R) — » GF occurred(R)). □ 

Finally, the property preservation theorem states that a successful verification of a property in the 
abstraction implies its truth in the original model. 
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Theorem 3. For a pathway P and a J C / where I is the component set of P and f an ACTL formula 
we have LTS a (P \J) / implies LTS(P) 1=$ /. 

Proof. By induction on the structure of / (for all s). 

f = s. By definition of state projection and the fact that APrs are pairwise disjoint, for all atomic 
propositions s from APj we get that LTS a (P\J),s \J l=<j> a s iff LTS(P),s N<j> s. Analogously for / = -is. 

/ = g A h. From the assumption LTS a (P \J) , s \J hi> a g A h by CTL semantics, LTS a (P \J) , s \J \=d, a 
g and LTS a (P\J),s\J t=$ h. By induction hypothesis LTS(P),s (=<j> g and LTS(P),s N$ /j. Hence, 
LTS(P) , s No^A/i. Case f = g\/ his proved analogously. 

/ = A[g t/». A]. Let 7T be an arbitrary fair maximal path starting in s. We establish LTS(P),Tl h<j> 
[g U w h]. By Lemma Q] at least one of n\J or n\°°J is a path in LTS a (P\J), and by Lemma [2] both are 
abstractly fair. 

Let us suppose first that n \J is the abstractly fair maximal path in LTS a (P\J)- Hence by the assump- 
tion LTS a {P\J),tt\J l=<j) a [g U w h]. There are two cases: 

1. LTS a (P\J),7c[J \=<t> a G g. Let t be any state along %. By CTL semantics LTS a (P\J),t\J h$ a g. 
By induction hypothesis we have LTS(P),t \=$, g. Since ? was an arbitrary state of 71, we get 
LTS(P),n N> G g and thus LTS(P),n ^ g U w h. 

2. LTS a {P\J),n\J N<£ a [g f/ h]. Let be the first state along n\J that satisfies h. Then there is 
at least one state s'" along % such that s m \J = sf . Let s m be first such state. By induction 
hypothesis LTS(P),s m \=$, h. From the definition of path projection any s m with m <m' projects 
to s m \J that is before sf in n\J. By the assumption LTS a (P\J) 1 s m \J g, hence by induction 
hypothesis LTS(P),s m N$ g. By CTL semantics we get LTS(P),n \=<&gU h. 

In both cases we showed LTS{P),7l l=$ g £/„ h. Since 71 was arbitrary fair maximal path starting in s, we 
conclude LTS(P),s \=<s>A[g U w h]. 

The reasoning for the case in which the abstractly fair maximal path in LTS a (P \J) is % \°°J is analo- 
gous to the considered case. 

f = A[gU h]. Let % be an arbitrary fair maximal path starting in s. By Lemmas Q] and |2] we have that 
7T \J or 7t [°°7 is a fair maximal path in LTS a (P \J) and by the assumption LTS a (P \J) , ft \J \=<^ a [g U h] or 
LTS a (P\J),7c\°°J\=* a [gU h}. By the above case we get LTS(P),s\=^A[g U h}. □ 

5 Experiments 

In this section we exploit the NuSMV model checker to perform some experiments on the model of 
the EGF pathway. NuSMV includes model checking algorithms that allow fairness constraints to be 
taken into account. We rely on such algorithms to manage fairness constraints introduced in this paper. 
Moreover, in order to carry out the projection and encode the resulting abstract pathway in the NuSMV 
format we have developed a tool (available upon request). 

The first experiment is aimed at showing how modular verification could be applied to verify a 
global property of the pathway, namely that the final product of the pathway is always produced. This 
can be done in a modular way by proving sub-properties in three different model fragments obtained by 
projection. 

Subsequently, a number of experiments are performed with the aim of showing how the molecular 
components we identified in the pathway can be used to better understand the pathway dynamics. In 
particular, we check whether there are some molecular components that are not really necessary to obtain 
the final product of the pathway. This will be done by applying model checking on models in which 
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molecular components are selectively disabled by setting their initial states to false. Also in this case the 
modular verification approach is adopted. 

In this case study modular verification allows properties to be verified faster than on the complete 
model. However, modular verification is still not significantly more efficient than verification on the 
complete model. This is due to the projection operation we are considering at the moment, which is 
rather rough. In Section [6] we discuss why this modular verification is a promising approach for the 
analysis of pathways, and how we plan to improve the approach to make it substantially more efficient. 

To run the experiment we used NuSMV 2.5.4 on a workstation equipped with an Intel i5 CPU 2.80 
Ghz, with 8GB RAM and running Ubuntu GNU/Linux. In order to make verification faster NuSMV 
was executed in batch mode by enabling dynamic reordering of BDD variables and by disabling the 
generation of counterexamples. 

5.1 Modular verification of a global property 

The final product of the MAP kinase cascade activated by surface and internalised EGF receptors is 
species ERK-PP. Since surface and internalised receptors activate two different branches of the pathway, 
we denote by ERK-PP the product of the branch activated by the surface receptors and by ERK-PPi the 
product of the branch activated by the internalised receptors. 
The property to be verified is 

AF (ERK-PP V ERK-PPi) (1) 

The property holds in the complete model and its verification required 260 seconds. By looking at 
the diagram in FigureQ]we noticed that the pathway could be partitioned in three parts, with two species 
acting as "gates". These two species are (EGF-EGFR*)2-GAP and Raf*. Hence, we decided to try to 
apply modular verification by splitting property Q] into the following three sub-properties: 

AF((EGF-EGFR*)2-GAP) (2) 
AG ( (EGF-EGFR* ) 2-G AP -> (AF Raf*)) (3) 
AG (Raf -»• AF (ERK-PP V ERK-PPi) ) (4) 

Property © states that in all paths of the system a state in which species (EGF-EGFR*)2-GAP is 
present is eventually reached. Property © states that whenever a state is reached in which species 
(EGF-EGFR* )2-GAP is present, then a state in which Raf* is present is eventually reached. Finally, 
property © states that whenever a state is reached in which in which species Raf* is present, then a state 
in which either ERK-PP or ERK-PPi is present is eventually reached. It is easy to see that the conjunction 
of ©, © and © implies ©. 

We considered three projections of the complete model to be used to verify properties ©, © and 
©, respectively. In particular, from the component interaction graph of the model (shown in Figure |2]) 
we extracted the following subsets to be used for projections: 

• in order to verify © we considered the subset J\ consisting of components EGF, EGFi, EGFR 
and GAP; 

• in order to verify © we considered the subset Ji consisting of components EGFR, GAP, She, 
RasGDP, Grbl and Sos; 

• in order to verify © we considered the subset Jt, consisting of components RasGDP, Raf, MEK, 
ERK, Phosphatase! , Phosphatase! and Phosphatase^ . 
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Table 1 : Model checking results and comparison of verification times 



We obtained that ©, © and © hold in the abstract semantics of the abstract pathways P\J\, Pf/2 
and Pf/3, respectively. Moreover, model checking required less than three seconds for ©, 213 seconds 
for © and less than one second for ©. Overall, modular verification required 217 seconds, that is 43 
seconds less than verification on the complete model. 

5.2 Reasoning on molecular components 

As it can be seen in the component interaction graph and in the diagram in Figure [Q some molecular 
components are involved in complex interactions. This is true in particular for components EGFR, GAP, 
RasGDP, Sos, She and Grb2 which form a clique in the component interaction graph. We are interested 
in understanding whether all of these components are really necessary in order to obtain the final products 
of the pathway. The idea is to test whether the final species are produced when the components of interest 
are assumed one by one as disabled. Molecular components EGFR and RasGDP are for sure necessary 
since they connect the clique with the other molecular components of the pathway. Consequently, we 
focus our analysis on GAP, Sos, She and Grb2. 

In order to disable a molecular component we consider as absent all of its species in the initial state of 
the systems. Hence, we consider a set of four (complete) models, each with one of the four components 
under study disabled. On each model we try to verify property ©: if the property does not hold, then 
the component that is disabled in such a model is necessary for the pathway; on the other hand, if the 
property holds, then the component turns out to be not necessary since the products of the pathway can 
be obtained even without it. The same tests can be also done in a modular way by decomposing the 
pathway and the property as in Section IBTTl 

In Table Q] we summarise the property verification results and compare verification times obtained 
by model checking the complete models and by following the modular approach. The first row of data 
in the table reports verification results in which no component is disabled (as in Section IBTTT ). The other 
results show that She is not a necessary component, whereas all of the other three are. As previously, the 
time required by modular verification is smaller than the one required by model checking the complete 
model. This is true in particular in the case in which GAP is disabled since property ©, the verification 
of which is very fast, turns out to be false. 
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Note that in the case of modular verification of the models in which GAP, Sos and Grbl were disabled 
we needed to verify some additional properties. In particular, in the case of GAP we have that property 
(121) does not hold in the abstract semantics of P \J\ , and in the cases of Sos and Grb2 property ® does 
not hold in the abstract semantics of P\J2- We remark that our modular verification approach guarantees 
only that properties proved to hold in a model fragment also hold in the complete model. Nothing can be 
said, instead, of properties that does not hold in the model fragments. In order to avoid applying model 
checking on the complete model to check whether these properties hold there, we consider some new 
properties whose satisfaction in suitable model fragments implies that properties (O and ([3]) actually do 
not hold. In order to prove that is actually false when GAP is disabled we consider the following 
property: 

AG ( -i (EGF-EGFR*) 2-GAP) (5) 

In order to prove that (O is actually false when either Sos or Grbl is disabled we consider the following 
property: 

AG(-iRaf*) (6) 

Note that it is convenient to verify properties (f5]) and © together with (f2]) and ([3]), respectively. This 
avoids spending twice the time needed by the model checker to construct the data structure necessary 
to perform the verification. In the case of our experiments the construction of such data structures takes 
usually the 98%-99% of the verification time. Times reported in Table Q] are based on this optimisation. 



6 Discussion and conclusions 

In this paper we presented preliminary results in the development of a modular verification framework 
for biochemical pathways. We defined a modelling notation for pathways associated with a formal 
semantics and a notion of fairness that allows the dynamics to be accurately described by avoiding 
starvation situations among reactions. Moreover, we investigated a notion of molecular component of a 
pathway and we provided a methodology to infer molecular components from pathways the reactions of 
which satisfy some assumptions. Molecular components were then used by a projection operation that 
allows abstract pathways modelling an over-approximation of the behaviour of a group of components 
to be obtained from a pathway model. The fact that a property expressed by means of the ACTL logic 
holds in an abstract pathway was shown to imply that they hold also in the complete pathway model. 
This preservation is at the basis of the modular verification approach which was demonstrated on a well- 
established model of the EGF pathway. 

The results of experiments given in Section [5] show that our modular verification approach allows 
properties to be verified in a shorter time than in the case of verification of the complete pathway model. 
However, in most of the cases the time saved was relatively small (~ 15%). We believe that the cause 
of this limited gain in efficiency is due to the projection operation we are considering at the moment, 
which is still somewhat rough. Our plan to improve efficiency is to define a projection operation that 
combines the current one (that essentially removes some molecular components from the model) with 
another that somehow minimises the description of components not removed by the model, but whose 
role in the property to be verified is marginal. In the case of the considered case study this would allow, 
for example, to reduce the size of the model of the components constituting the clique in the component 
interaction graph in Figure [2] by focusing on components EGFR and RasGDP, and by minimising the 
description of components GAP, She, Sos and Grbl. This would allow for a significant improvement in 
modular verification efficiency. 



80 



Towards modular verification of pathways: fairness and assumptions 



References 

[1] Paul C. Attie & E. Allen Emerson (1998): Synthesis of concurrent systems with many similar processes. ACM 
Transactions on Programming Languages and Systems 20(1), pp. 51-1 15, doi: 10. 1145/271510.271519[ 

[2] Roberto Barbuti, Andrea Maggiolo-Schettini, Paolo Milazzo & Angelo Troina (2006): A Calculus of Looping 
Sequences for Modelling Microbiological Systems. Fundamenta Informaticae 72(1-3), pp. 21-35. 

[3] Jerry R. Burch, Edmund M. Clarke, Kenneth L. McMillan, David L. Dill & L. J. Hwang (1992): Symbolic 
Model Checking: 10 20 States and Beyond. Information and Computation 98(2), pp. 142-170, doi jlO . 1016/ 
0890 -5401 (92) 90017-A| 

[4] Luca Cardelli (2005): Brane Calculi. Computational Methods in Systems Biology, pp. 257-278, doi jlO . 
|1007/978-3-540-25974-9_24| 

[5] Alessandro Cimatti, Edmund Clarke, Enrico Giunchiglia, Fausto Giunchiglia, Marco Pistore, Marco Roveri, 
Roberto Sebastiani & Armando Tacchella (2002): NuSMV Version 2: An OpenSource Tool for Symbolic 
Model Checking. In: Proc. International Conference on Computer-Aided Verification (CAV 2002), LNCS 
2404, Springer, Copenhagen, Denmark, pp. 241-268, doi jlO . 1007/3-540-45657-0_29| 

[6] Federica Ciocchetta & Jane Hillston (2009): Bio-PEPA: A framework for the modelling and analysis of 
biological systems. Theoretical Computer Science 410(33-34), pp. 3065-3084, doi:1 . 1016/j .tcs.2009. 

102.0371 

[7] Edmund M. Clarke, Orna Grumberg & David E. Long (1994): Model checking and abstraction. ACM Trans- 
actions on Programming Languages and Systems 16(5), pp. 1512-1542, doi:10 .1145/186025 . 186051. 

[8] Edmund M. Clarke, Orna Grumberg & Doron Peled (1999): Model Checking. MIT Press. 

[9] Vincent Danos & Cosimo Laneve (2004): Formal molecular biology. Theoretical Computer Science 325(1), 
pp. 69-1 10, doi jl0.1016/j .tcs.2004.03.065| 

[10] Peter Drabik, Andrea Maggiolo-Schettini & Paolo Milazzo (2010): Dynamic Sync-programs for Modular 
Verification of Biological Systems. In: 2nd Int. Workshop on Non-Classical Models of Automata and appli- 
cations (NCMA'10), 263, Austrian Computer Society, Jena, Germany, pp. 71-83. 

[1 1] Peter Drabik, Andrea Maggiolo-Schettini & Paolo Milazzo (2010): Modular Verification of Interactive Sys- 
tems with an Application to Biology. Electronic Notes in Theoretical Computer Science 268, pp. 61-75, 
doi jlO . 1016/j .elites. 2010 .12. 006| 

[12] Peter Drabik, Andrea Maggiolo-Schettini & Paolo Milazzo (201 1): Modular Verification of Interactive Sys- 
tems with an Application to Biology. Scientific Annals of Computer Science 21, pp. 39-72. 

[13] E. Allen Emerson & Chin-Laung Lei (1987): Modalities for model checking: branching time logic strikes 
back. Science of Computer Programming 8, pp. 275-306, doi jlO . 1016/0167-6423( 87) 90036^0} 

[14] Francois Fages, Sylvain Soliman & Nathalie Chabrier-Rivier (2004): Modelling and querying interaction 
networks in the biochemical abstract machine biocham. Journal of Biological Physics and Chemistry 4, pp. 
64-73. 

[15] John Heath, Marta Kwiatkowska, Gethin Norman, David Parker & Oksana Tymchyshyn (2008): Probabilis- 
tic model checking of complex biological pathways. Theoretical Computer Science 391(3), pp. 239-257, 
doi jlCT. 1016/j .tcs.2007.11.013| 

[16] Pedro T. Monteiro, Delphine Ropers, Radu Mateescu, Ana T. Freitas & Hidde de Jong (2008): Temporal logic 
patterns for querying dynamic models of cellular interaction networks. Bioinformatics 24(16), pp. 227-233, 
doi jlO . 1093/bioinf ormatics/btn275l 

[17] Amir Pnueli (1981): The temporal semantics of concurrent programs. Theoretical Computer Science 13(1), 
pp. 45 - 60, doi: 1 0.1016/0304-3975(81)90110-91 

[18] Corrado Priami, Aviv Regev, Ehud Shapiro & William Silverman (2001): Application of a stochastic name- 
passing calculus to representation and simulation of molecular processes. Information Processing Letters 
80(1), pp. 25-31, doi j 10 . 1016/S0020-0190 (01) 00214-9[ 



P. Drabik, A. Maggiolo-Schettini and P. Milazzo 



81 



[19] Aviv Regev, Ekaterina M. Panina, William Silverman, Luca Cardelli & Ehud Shapiro (2004): BioAmbients: 
an abstraction for biological compartments. Theoretical Computer Science 325(1), pp. 141-167, doi jlO . 
1016/j .tcs.2004.03.06H 

[20] Birgit Schoeberl, Claudia Eichler-Jonsson, Ernst Dieter Gilles & Gertraud Muller (2002): Computational 
modeling of the dynamics of the MAP kinase cascade activated by surface and internalized EGF receptors. 
Nature Biotechnology 20(4), pp. 370-375, doi jlO . 1038/nbt0402-370l 



